Download Publication PDF
EternaX Research · Q3 2026 Edition · Report #9 · FINAL · · Updated Quarterly

Quantum Value at Risk (QVaR) 2026: $796.7B in Institutional Digital-Asset Exposure to Quantum Risk

Measuring Asset QVaR, Flow QVaR and Settlement QVaR Across Stablecoins, Custody, Tokenized Assets and Institutional Blockchain Infrastructure

Boards · Risk Committees · CISOs · Digital Asset Teams · Stablecoin Issuers · Custodians · Settlement Operators

Data cut: September 7, 2026. Historical September 1 snapshots used where available. Public inputs are sourced facts; Asset/Flow QVaR, CVF and migration-readiness scores are modeled; EternaX testnet results are identified separately.

Gross Control-Surface QVaR
$796.7B MODELED
Asset QVaR · current standing exposure
Stablecoin A-QVaR$212.2B
Custody/MPC A-QVaR$396.3B
Public-chain A-QVaR$179.8B
Tokenized-fund A-QVaR$8.4B
Settlement QVaRInstitution-specific
Canton Flow QVaR$4.8T+/month
Global equity + fixed income market $318.5T
Key Findings
1
Asset QVaR across the 28 assessed programmes is $796.7 billion. It measures standing economic value governed by currently vulnerable cryptographic control surfaces.
2
Flow QVaR is network-agnostic. Canton is the strongest institutional example at $4.8T+/month; Stellar's $11.4B of Q2 2026 stablecoin transfer volume produces an illustrative $9.12B/quarter stablecoin Flow QVaR at CVF 0.80.
3
Settlement QVaR is a third, institution-specific measure: value that can become economically exposed during the compromise-to-detection-to-containment and settlement window.
4
Asset QVaR, Flow QVaR and Settlement QVaR are not added together. They measure stock value, value-throughput per period, and attack-window financial exposure respectively.
5
26 of 28 assessed programmes lack a publicly evidenced end-to-end PQ migration path; migration readiness is reported separately and does not reduce today’s QVaR merely because a roadmap exists.
6
The protocol benchmark covers 15 networks, while the larger strategic market context remains $318.5T of global listed equities plus fixed-income securities outstanding.

The Two Charts That Define the QVaR Thesis

The first chart separates the three dimensions of quantum financial exposure while connecting them to live institutional tokenization activity. The second shows the migration-readiness gap across the assessed programmes.

The market-infrastructure chart
Capital Markets Are Moving On-Chain — QVaR Measures Stock, Flow and Settlement Exposure Separately
A Tier-1 risk view cannot mix assets outstanding with transaction throughput. QVaR therefore separates standing Asset QVaR, period-based Flow QVaR and institution-specific Settlement QVaR.
Addressable capital-market base
$318.5T
Global listed equities + fixed-income securities outstanding in 2025. This is market context, not current on-chain value.
Institutional rails already moving on-chain
>$114T
Assets currently custodied at DTC
$6T+ / month
Canton value processed monthly
$351B/day
Broadridge DLR tokenized repo average daily volume in August
$300B
Coinbase Institutional assets under custody
Quantum financial exposure
$796.7B
Asset QVaR — standing value governed by scored vulnerable controls
$4.8T+/month
Canton Flow QVaR — modeled vulnerability-adjusted monthly throughput
Institution-specific
Settlement QVaR — attack-window exposure after limits, DvP/netting, finality, detection and recovery
Takeaway: Flow QVaR is not Canton-only. Canton is the clearest institutional example because its network throughput is publicly disclosed at $6T+ per month. Other networks also have Flow QVaR, but the report keeps flow classes separate rather than mixing repo settlement, stablecoin transfers, payments and trading volume.
The urgency chart
The Quantum Migration Gap: 26 of 28 Have No Public End-to-End PQ Path
The strongest institutional finding in the report is not that quantum risk exists. It is that the migration path is still largely absent in public evidence while cryptographic transition windows are moving closer.
Lack a public end-to-end PQ migration path
92.9%
26 / 28
Disclose end-to-end PQ remediation today
0 / 28
Takeaway: 92.9% of assessed programmes lack a publicly evidenced end-to-end migration path, and none disclose completed end-to-end PQ remediation across the relevant control surfaces. That is the report's core readiness gap.
2026
Current QVaR assessment and migration-planning baseline.
2030
EO 14412: PQ key establishment deadline for specified Federal high-value/high-impact systems; FAR process also points to 2030 for covered contractors.
2031
EO 14412: PQ digital-signature deadline for specified Federal high-value/high-impact systems.
2035
NIST IR 8547 draft transition horizon includes broader disallowance of classical public-key signatures depending on algorithm/security strength.
Migration-gap figures are modeled from publicly evidenced status. Regulatory milestones below are sourced facts.

QVaR in 60 Seconds: Direct Answers

What is Quantum Value at Risk?

QVaR is an umbrella framework for measuring quantum-related financial exposure across three dimensions: Asset QVaR, Flow QVaR and Settlement QVaR.

What does $796.7B mean?

$796.7B is modeled Asset QVaR: standing economic value governed by the scored quantum-vulnerable control surfaces in the 28-programme register.

What does $4.8T+/month mean?

Canton reports $6T+ processed monthly. Applying the report's current vulnerability factor of 0.80, with no credited network-wide deployed PQ mitigation, gives $4.8T+/month of modeled Flow QVaR. It is throughput exposure, not $4.8T of unique assets.

What is Settlement QVaR?

Settlement QVaR estimates how much value can become economically exposed during a defined compromise, detection, containment and settlement window after accounting for control scope, limits, DvP/netting, reversibility and loss severity.

Does a PQ roadmap reduce current QVaR?

No. Migration Readiness Score is reported separately. A plan or roadmap improves readiness but does not make today's classical cryptographic control safer.

Can Asset QVaR and Flow QVaR be added?

No. Asset QVaR is measured in dollars at a point in time; Flow QVaR is measured in dollars per day or month. They are complementary but dimensionally different.

Which networks are explicitly benchmarked?

The benchmark covers 15 networks in source order: EternaX, Zcash, Canton, Ethereum, Solana, Arc, Tempo, Hyperledger Besu, Stellar, Starknet, Sui, Aptos, NEAR, Algorand and XRP Ledger.

What should an institution do first?

Inventory cryptographic control surfaces, calculate Asset and Flow QVaR, then use private transaction/finality/control data to calculate Settlement QVaR and prioritize remediation.

Why Institutional Digital Assets Need a Quantum Risk Metric

Data basis. Public market/AUM/network and transaction-flow inputs are sourced facts. Asset/Flow QVaR, CVF and migration-readiness scores are modeled. Migration readiness is not used to discount current QVaR. EternaX 3/3 core-layer coverage refers to internal testnet results. Data cut: September 7, 2026.
$318.5T
Global listed equities + fixed-income securities outstanding (2025). Addressable market context.
$796.7B
Asset QVaR — standing value governed by scored vulnerable control surfaces.
$4.8T+/mo
Canton Flow QVaR — modeled vulnerability-adjusted monthly transaction throughput.
Institution-specific
Settlement QVaR — attack-window exposure requiring private settlement/control data.

Institutional digital-asset infrastructure already governs hundreds of billions of dollars in stablecoins, tokenized funds, custody balances, and on-chain settlement flows. The larger strategic context is much bigger: SIFMA reports $157.8 trillion of global equity market capitalization and $160.7 trillion of global fixed-income securities outstanding for 2025 — a combined $318.5 trillion capital-market base. This report does not assume all $318.5T will move on-chain. It treats that figure as the addressable financial-market base against which tokenization is expanding, making cryptographic resilience a market-infrastructure question rather than a crypto-only question. Primary source: SIFMA 2026 Capital Markets Fact Book findings.

The policy timeline requires precision. NIST IR 8547 remains an Initial Public Draft: it proposes deprecation after 2030 for 112-bit ECDSA/RSA parameter sets and disallowance after 2035, while 128-bit-or-higher ECDSA and EdDSA are proposed to be disallowed after 2035. Executive Order 14412 directly requires Federal high-value assets and high-impact systems to transition key establishment by December 31, 2030 and digital signatures by December 31, 2031, and separately directs the FAR Council to propose requirements for covered contractors. These dates are important institutional planning signals; they are not a universal statutory deadline for every private blockchain operator. FIPS 140-2 validated modules remain on the active CMVP list through September 21, 2026 and are scheduled to move off the active list on September 22, 2026. NIST IR 8547 · EO 14412 · NIST CMVP.

Institutional risk committees already separate stocks, flows and settlement exposures in other risk domains. QVaR applies the same discipline to quantum cryptographic risk: Asset QVaR measures standing value, Flow QVaR measures quantum-critical throughput over a defined period, and Settlement QVaR estimates the value economically exposed during an institution-specific attack and settlement window. Flow QVaR is network-agnostic: any network carrying economic transactions can be scored once a comparable flow class and time horizon are defined.

$318.5T Capital Markets Are Moving Onto Cryptographic Rails

SIFMA reports $157.8T of global equity market capitalization and $160.7T of global fixed-income securities outstanding for 2025 — $318.5T combined. This is addressable capital-market context, not a claim that $318.5T is already tokenized or quantum-exposed.

The relevant signal is that real institutional infrastructure is already moving securities, collateral, funds and settlement workflows onto cryptographic rails. Tokenization forecasts reinforce the direction of travel: BCG’s 2026 middle-of-the-road scenario estimates $14T by 2030 and $55T by 2035; Standard Chartered and Synpulse project $30.1T by 2034. These are forecasts, not current on-chain value.

Sources: SIFMA · DTCC/DTC · BCG · Standard Chartered.

Institutional Adoption Is Already Live

The evidence is not the forecast itself. It is the live activity already visible across market infrastructure, custody, tokenized funds and institutional settlement.

Canton Network
$6T+/month processed
Canton reports $6T+ processed monthly and $350B+ daily tokenized U.S. Treasury repo activity. Under the QVaR framework this is modeled as Flow QVaR, not treated as $6T of unique assets outstanding.
DTC / DTCC
>$114T custody base
DTC currently custodies more than $114T of assets. DTCC successfully processed live production trades using DTC-tokenized assets in July 2026, with about 40 firms participating, ahead of the planned October 2026 service launch.
DTCC Industry Working Group
50+ firms
Participants span custodians, banks, asset managers, brokers and infrastructure providers, including Bank of America, BlackRock, BNP Paribas, Citi, Goldman Sachs, HSBC, Franklin Templeton, Fireblocks and Digital Asset.
Broadridge DLR / Canton
$351B/day
Broadridge’s Distributed Ledger Repo processed $351B average daily repo volume and $7.4T total volume in August 2026, demonstrating institutional-scale tokenized financing and collateral activity.
BlackRock
~$150B digital-asset AUM
BlackRock says it has nearly $150B in AUM connected to digital assets, including the world’s largest tokenized treasury fund, roughly $65B of stablecoin reserves and nearly $80B of digital-asset ETPs.
Franklin Templeton / BENJI
$1.98B AUM
BENJI is the first U.S.-registered mutual fund to use a public blockchain as its official system of record. The BENJI suite represented $1.98B in AUM as of April 29, 2026.
Coinbase Institutional
$300B custody
Coinbase reports $300B in assets under custody and $236B in quarterly institutional trading volume, showing the scale of cryptographic custody and transaction infrastructure already serving institutional markets.
Why this matters for QVaR. Institutional adoption increases the value governed by cryptographic control surfaces. QVaR measures the current exposed subset; the market-infrastructure transition determines how large that dependency can become.
QVaR implication. The strategic issue is not that the entire $318.5T market is already exposed. It is that more institutional value is becoming dependent on cryptographic control surfaces before those controls are fully post-quantum safe. Asset QVaR measures today’s standing exposed subset; Flow and Settlement QVaR measure the economic activity and attack-window exposure that grow as adoption scales.

QVaR Glossary: Core Terms

QVaR
Quantum Value at Risk. An umbrella framework for Asset QVaR, Flow QVaR and Settlement QVaR.
A-QVaR
Asset Quantum Value at Risk. Standing economic value governed by a quantum-vulnerable cryptographic control surface after current vulnerability and deployed mitigation are applied.
F-QVaR
Flow Quantum Value at Risk. Quantum-critical transaction value passing through vulnerable cryptographic authorization over a defined horizon, expressed as $/day, $/month or another period.
S-QVaR
Settlement Quantum Value at Risk. Institution-specific value that can become economically exposed during the effective compromise-to-detection-to-containment and settlement window.
QCE
Quantum-Critical Exposure. Standing dollar value governed by a quantum-vulnerable control surface.
QCF
Quantum-Critical Flow. Transaction value passing through a quantum-vulnerable control surface during a defined period.
CVF
Current Vulnerability Factor. Ordinal factor for the current architecture and operational barriers around a classical cryptographic control. Higher means greater current exposure.
DME
Deployed Mitigation Effectiveness. Credit only for mitigation that is actually deployed and demonstrably reduces the affected quantum-vulnerable control surface.
MRS
Migration Readiness Score. Separate ordinal score for publicly evidenced progress toward post-quantum migration. A roadmap does not reduce current QVaR.
LSF
Loss Severity Fraction. Institution-specific fraction of attack-window flow that can become economically unrecoverable after limits, DvP/netting, reversibility, recovery and compromised-control scope.
CRQC
Cryptographically Relevant Quantum Computer. Quantum computer capable of practically breaking deployed cryptography at real-system scale.
Gross A-QVaR
Non-deduplicated Asset QVaR across independent control surfaces; the same underlying asset can appear more than once.
End-to-end PQ
All relevant authorization, identity, custody, consensus, privacy and settlement cryptographic dependencies have a verified PQ path without a defeating classical fallback.

QVaR Methodology: Asset, Flow and Settlement Exposure

Quantum Value at Risk is an umbrella financial-exposure framework, not conventional statistical market VaR. This edition does not claim a loss probability, confidence interval or CRQC arrival forecast. It separates three quantities that should never be collapsed into one number.

1 · Standing exposure
Asset QVaR
How much standing economic value is governed by currently vulnerable cryptographic controls?
A-QVaR = QCE × CVF × (1 − DME)
2 · Throughput exposure
Flow QVaR
How much economic value passes through vulnerable cryptographic authorization during horizon h?
F-QVaRₕ = QCFₕ × CVF × (1 − DME)
3 · Attack-window exposure
Settlement QVaR
How much value can become economically exposed before compromise is detected, contained and settlement risk is neutralized?
S-QVaRᵥ = QCF rate × window × CVF × (1 − DME) × LSF
Dimensional rule. Asset QVaR is a stock measure in dollars. Flow QVaR is a rate such as dollars/day or dollars/month. Settlement QVaR is attack-window dollar exposure. They are complementary and must not be added together.
Network-agnostic rule. F-QVaR applies to any network, custodian or settlement rail carrying quantum-critical transaction flow. Canton is the lead public example in this edition because its institutional throughput is explicitly disclosed. Other networks should be scored only after fixing a comparable flow class and time horizon.

Current Vulnerability Factor (CVF)

CVF expresses the fraction of economic exposure that remains dependent on vulnerable classical cryptography after current operational barriers are considered. Higher values therefore indicate greater current cryptographic vulnerability.

Current architectureCVFInterpretation
Single ECDSA EOA0.95One classical key controls the full authorization surface.
ECDSA multisig (2-of-3)0.80Thresholding improves operations; all signing primitives remain classically vulnerable.
ECDSA multisig (3-of-5+)0.70Higher threshold reduces operational exploitability but not the underlying quantum vulnerability.
MPC threshold ECDSA0.75Key shares are distributed, but the aggregate authorization primitive still relies on elliptic-curve hardness.
Hardware-backed multisig / HSM0.60Strong classical custody controls; the public authorization primitive remains classical.
Time-locked + multisig0.55Detection/response window reduces operational loss potential but does not make the signature PQ-safe.
Institutional-grade HSM + multisig + monitoring0.50Maximum operational defence in this scale without deployed PQ cryptographic remediation.

Deployed Mitigation Effectiveness (DME)

DME receives credit only for controls deployed today that demonstrably reduce the affected quantum-vulnerable surface. A future roadmap, research programme or announced migration date does not reduce current A-QVaR or F-QVaR. In this public register, no broad stock-exposure row receives network-wide DME credit.

Migration Readiness Score (MRS) — reported separately

Migration statusMRS
No disclosed PQ migration plan0.00
PQ assessment or intention stated publicly0.05
PQ plan disclosed with timeline and scope0.15
PQ implementation in progress / partial surfaces0.35
PQ hybrid deployment across relevant surfaces0.65
PQ-native across relevant surfaces without defeating classical fallback0.95

MRS is not a current-risk discount. It measures preparedness and future risk trajectory. Two systems using the same vulnerable signature primitive today can have different migration readiness while having the same current cryptographic exposure.

Canton Flow QVaR example

Canton public throughput: $6T+ / month
CVF: 0.80
Network-wide deployed PQ mitigation credited in this public model: 0.00

F-QVaR = $6T+ × 0.80 = $4.8T+ / month

Canton also reports $350B+ daily tokenized U.S. Treasury repo activity. On the same illustrative CVF basis, that is $280B+/day of vulnerability-adjusted flow. Do not add the daily and monthly values, and do not add Flow QVaR to Asset QVaR.

Settlement QVaR example

If a system processes $350B/day, a 30-minute gross activity window corresponds to approximately $7.29B of flow before applying CVF, deployed mitigation and the institution-specific Loss Severity Fraction. S-QVaR then adjusts for the actual compromised key/control scope, transaction limits, DvP/netting, finality, reversibility, detection, containment and recovery mechanisms.

Public QVaR inputs derive from issuer/market supply, fund/provider AUM, network asset footprint, custody disclosures/estimates and transaction-flow disclosures. Gross Asset QVaR can overlap across independent control surfaces by design. Broadridge DLR activity is not added to Canton Flow QVaR because it is an identifiable workflow within the Canton ecosystem and would create double counting.

The QVaR Register: Asset QVaR + Quantum-Critical Flow Across 28 Programmes

Stock-exposure rows report Asset QVaR. Canton reports Flow QVaR because the public metric is transaction throughput rather than unique assets outstanding. CVF measures current vulnerability; MRS is shown separately and does not reduce current A-QVaR/F-QVaR.

#Institution / ProgrammeChain(s)Economic exposure / flowCVFMRSA-QVaR / F-QVaRPrimary exposure
Stablecoin Issuers — $212.2B Asset QVaR
1Tether / USDTEthereum, Tron, +183.34 0.800.00146.7 Admin mint/burn/pause authority; architecture semi-opaque
2Circle / USDCEthereum, Solana, +73.42 0.700.0051.4 Admin, mint, freeze, blacklist; known multisig
3MakerDAO / DAI+USDSEthereum14.40 0.600.008.6 Governance multisig; multi-collateral controls
4Ethena / USDeEthereum4.12 0.800.003.3 Minting/redemption authority; delta-neutral position keys
5First Digital / FDUSDEthereum, BNB0.34 0.800.000.27 Admin/mint authority
6PayPal / PYUSDEthereum, Solana2.93 0.650.001.9 Paxos-managed admin; institutional-grade ops
Tokenized Funds — $8.4B Asset QVaR
1BlackRock-Securitize / BUIDLEthereum, Polygon, +~2.800.700.002.0Smart contract owner/admin; Securitize infra
2Ondo Finance / OUSG + USDYEthereum, Solana, +2.52 0.750.001.9 Token admin, redemption gating, compliance keys
3Hashnote / USYCEthereum~2.800.750.002.1Token admin; yield distribution controls
4Hamilton LanePolygon, Stellar0.60 0.700.000.4 Fund admin; transfer restriction controls
5Franklin Templeton / BENJIStellar, Polygon, +1.98 0.700.001.4 Token admin; Stellar Ed25519 chain dependency
6Superstate / USTBEthereum0.78 0.750.000.6 Token admin; compliance and transfer controls
7JPMorgan / JLTXXEthereum (Kinexys)0.100.550.000.06 $100M JPMorgan launch investment; tokenized government money-market fund on Ethereum
Custody and MPC — $396.3B Asset QVaR
1Coinbase Custody (Prime)Multi-chain300 0.650.00195.0 Bitcoin ETF custody, institutional prime; ECDSA keys
2FireblocksMulti-chain~150 0.750.00112.5 MPC-CMP; ECDSA threshold shares
3Anchorage DigitalMulti-chain~50 0.700.0035.0 Federally chartered; ECDSA custody infra
4BitGoMulti-chain~40 0.700.0028.0 Multisig ECDSA; qualified custodian
5CopperMulti-chain~15 0.750.0011.3 ClearLoop MPC; ECDSA threshold
6KomainuMulti-chain~10 0.700.007.0 Nomura/CoinShares JV; institutional MPC
7Hex TrustMulti-chain~8 0.750.006.0 Licensed custodian; MPC ECDSA
8FordefiMulti-chain~2 0.750.001.5 MPC with policy engine; ECDSA threshold
Public Chains — $179.8B Asset QVaR + Canton $4.8T+/month Flow QVaR
1Canton NetworkInstitutional L1 / Global Synchronizer$6T+/month processed 0.800.35$4.8T+/month$6T+ monthly throughput; $350B+ daily tokenized U.S. Treasury repo; Flow QVaR is a rate, not unique assets
2EthereumMainnet$177.48B 0.800.05$141.98BDistributed + represented RWAs + stablecoins; ECDSA accounts, BLS consensus and KZG/curve dependencies
3SolanaMainnet$20.52B 0.800.10$16.42BDistributed + represented RWAs + stablecoins; Ed25519 user keys; PDAs off-curve; consensus remains classical
4AvalancheC-Chain$13.56B 0.800.00$10.85BDistributed + represented RWAs + stablecoins; validator secp256k1 and subnet/admin dependencies
5ArbitrumL2 (Ethereum)$5.18B 0.800.00$4.14BDistributed + represented RWAs + stablecoins; sequencer and bridge/admin cryptographic dependencies
6Polygon PoSMainnet$4.32B 0.800.00$3.46BDistributed + represented RWAs + stablecoins; validator ECDSA and bridge/admin dependencies
7StellarMainnet$3.75B 0.800.00$3.00BDistributed + represented RWAs + stablecoins; classic accounts use Ed25519; PQ signer type is roadmap work

Interpretation: public-chain stock rows use network asset footprint and report Asset QVaR. Canton reports $6T+ processed monthly and is therefore modeled as $4.8T+/month Flow QVaR at CVF 0.80. Broadridge's $351B/day DLR volume is a Canton workflow and is not added again. MRS is readiness information, not a current-risk discount.

Stablecoin Asset QVaR: $212.2B

Using September 1, 2026 circulating market-cap inputs, USDT carries $146.7B Asset QVaR and USDC $51.4B Asset QVaR. The six stablecoin issuers total $212.2B Asset QVaR. Public supply values are sourced inputs; CVF and Asset QVaR are modeled.

USDT is the largest stablecoin exposure at $146.7B Asset QVaR; USDC is $51.4B. The difference reflects the report’s current vulnerability factors applied to the September 1 supply values. Migration readiness is tracked separately and does not discount current exposure.

Under the GENIUS Act (enacted July 2025), payment stablecoin issuers must meet reserve, redemption, and disclosure requirements. No quantum-readiness requirement exists in the current framework. The GENIUS Act's permitted issuers collectively govern over $200 billion in circulating supply on ECDSA-dependent admin keys.

Custody and MPC Asset QVaR: $396.3B

Coinbase reports $300B assets under custody, producing $195.0B QVaR at CVF 0.65. The remaining custody exposure bases without exact public AUC are modeled estimates. Threshold MPC improves classical key-management resilience but does not make the underlying ECDSA signature primitive post-quantum secure.

Within custody, Coinbase Custody is the largest modeled exposure at $195.0B, followed by Fireblocks at $112.5B. Coinbase’s $300B custody figure is public; the other custody exposure bases marked with ~ are modeled estimates.

Is your custody provider in this register? EternaX PQ Custody SDK adds dual-gate SLH-DSA authorization beneath existing MPC, HSM, and multisig workflows. No provider replacement.

Scope a Custody Pilot

Tokenized Fund Asset QVaR: $8.4B

Tokenized fund QVaR is smaller in absolute terms but carries distinct risk. Fund admin keys control investor compliance claims (accreditation, jurisdiction, transfer eligibility), NAV updates, and redemption gating. Compromise of these keys can simultaneously freeze redemptions, manipulate reported NAV, and bypass transfer restrictions. BlackRock's BUIDL at $2.0 billion and Ondo's combined OUSG/USDY at $1.8 billion represent the largest exposures. Franklin Templeton's BENJI on Stellar faces additional chain-level risk because Stellar's Ed25519 permanently exposes every account's public key.

The tokenized fund category is growing rapidly: total tokenized RWA AUM exceeded $31 billion by mid-2026, with BCG projecting $14 trillion by 2030 and $55 trillion by 2035, while Standard Chartered and Synpulse project $30.1 trillion by 2034. Every dollar of new issuance on ECDSA-dependent infrastructure compounds QVaR. The EternaX PQ-ONCHAINID, PQ-Permit, and PQ-4626 controls protect issuer authority, compliance claims, and vault governance on supported EVM deployments without requiring contract redeployment.

Network Asset & Flow QVaR: $179.8B Standing Exposure + $4.8T+/month Canton Flow

For public chains with observable stock value, this edition calculates Asset QVaR from network asset footprint. Ethereum’s $177.48B footprint produces $141.98B A-QVaR at CVF 0.80; Solana’s $20.52B footprint produces $16.42B A-QVaR. Migration-readiness scores remain visible but do not discount current exposure.

Flow QVaR is network-agnostic. Every network carrying economic transactions has quantum-critical flow. Canton is the lead institutional example because it publicly reports $6T+ processed monthly and $350B+ daily tokenized U.S. Treasury repo activity. At CVF 0.80 and DME 0.00, the report models $4.8T+/month F-QVaR. Flow is a rate, not unique assets outstanding, and it is never added to Asset QVaR.

Comparable Flow QVaR Examples

Comparability rule. Flow QVaR must retain both its flow class and time horizon. Institutional repo settlement, stablecoin transfers, RWA transfers, payments and trading volume are different economic activities and should not be combined as though they were one homogeneous flow.
Canton
$4.8T+/month
Institutional Flow QVaR

$6T+ monthly network throughput × 0.80 CVF. Canton separately reports $350B+ daily tokenized U.S. Treasury repo activity.

Primary source ↗
Stellar
$9.12B / Q2
Stablecoin Flow QVaR

$11.4B of Q2 2026 stablecoin transfer volume × 0.80 CVF. This is a different flow class and is not directly comparable to Canton institutional throughput.

Primary source ↗
Network-agnostic interpretation. Ethereum, Solana, Avalanche, Arbitrum, Polygon, XRPL and other networks also have Flow QVaR. They are not separately scored in this edition unless a reproducible, class-specific flow metric and time horizon are selected. Broadridge DLR’s $351B/day average repo volume and $7.4T August 2026 volume are evidence of institutional activity within the Canton ecosystem and are not added again to Canton Flow QVaR.

Top 15 Network Post-Quantum Readiness Benchmark

This section expands the protocol analysis to the first 15 networks in the supplied benchmark, preserving the exact source order: EternaX, Zcash, Canton Network, Ethereum, Solana, Arc, Tempo, Hyperledger Besu, Stellar, Starknet, Sui, Aptos, NEAR, Algorand, and XRP Ledger. The table is intentionally detailed evidence; the report-level hero charts above focus on the two findings with the highest institutional and media significance.

How to read this benchmark. Composite readiness is not the same as live full-stack PQ deployment. A network can have meaningful research, standards selection or migration work while still lacking production PQ coverage across transactions, consensus and privacy. The table therefore keeps score, live coverage and compliance-readiness separate.
15networks assessed
12 / 15receive 0/3 core PQ-layer coverage today
3 / 3EternaX internal testnet core-layer coverage
Open the full 15-network post-quantum readiness benchmark
#NetworkScore PQ Core Transactions & ExecutionConsensus & FinalityPrivacy & ConfidentialityFull-Stack Crypto-AgilityStandardsPost-Quantum Compliance Readiness
01 EternaX 93 3/3 INTERNAL TESTNET PQ-safe · SLH-DSA · testnet PQ-safe · testnet PQ-safe · institutional privacy · testnet Full-stack · independent scheme migration FIPS 203 / 205 · finalized standards alignment PQ standards aligned · module validation deployment-specific
02 Zcash 50 0/3 Current spend authorization remains classical; Ironwood quantum recoverability is live on mainnet Not PQ-safe · no PQ consensus credited Quantum recoverability live; recoverability ≠ PQ-safe authorization NU6.3 Ironwood live; full PQ authorization migration not demonstrated Ironwood Quantum Recoverability live since July 28, 2026 Not end-to-end PQ; quantum recoverability is live
03 Canton Network 62 0/3 ML-DSA signing available behind experimental flag; production migration incomplete Not PQ-safe · production crypto remains ECC Not PQ-safe · strong privacy, but not PQ Extensible crypto API; broader PQC implementation planned over 6–12 months ML-DSA experimental now; broader signing/encryption migration planned Not end-to-end PQ today; active native PQC migration
04 Ethereum 56 0/3 Not PQ-safe · production authorization today Not PQ-safe · production consensus today Not PQ-safe · no protocol-wide PQ privacy Dedicated PQ team; Lean Ethereum roadmap targets core PQ infrastructure ~2029 NIST-aware PQ roadmap; leanXMSS / leanVM work Not end-to-end PQ today; active multi-layer migration
05 Solana 52 0/3 Ed25519 protocol transactions; Winternitz Vault is a deployed opt-in PQ primitive Current consensus remains classical; Alpenglow introduces BLS, also not PQ Not PQ-safe · public by default Migration path researched; no protocol-wide PQ switch live Evaluating Falcon and alternatives; no finalized protocol-wide FIPS-PQ scheme live Not end-to-end PQ today; proactive migration work
06 Arc 58 0/3 SLH-DSA supported for developers/wallets today; core transaction signatures remain ECDSA Not PQ-safe · validator PQ is future work Not PQ-safe · privacy not PQ-durable PQ developer/wallet path live; final PQ transaction signature not yet selected FIPS 205 SLH-DSA support live; ECDSA remains transaction baseline Not end-to-end PQ; public mainnet scheduled Sep. 16, 2026
07 Tempo 54 0/3 Not PQ-safe · no PQ signature live Not PQ-safe · no PQ consensus credited Not PQ-safe · privacy not PQ-durable Not full-stack · authentication interface only; no PQ stack migration demonstrated No PQ standard live today Not PQ compliant today · no PQ signature or KEX standard live
08 Hyperledger Besu 38 0/3 Not PQ-safe upstream · Ethereum transaction signatures Not PQ-safe upstream · QBFT validator signing Not PQ-safe by default · enterprise privacy ≠ PQ privacy Not full-stack · upstream core PQ migration requires custom work No upstream PQ standard today Not PQ compliant upstream · native PQ transaction / QBFT baseline not present
09 Stellar 37 0/3 Not PQ-safe · Ed25519 accounts Not PQ-safe · no PQ consensus credited Not PQ-safe · public by default Quantum Preparedness Plan: PQ verification in Soroban, then signer migration ML-DSA-44 / ML-DSA-65 planned as Soroban host functions Not PQ compliant today; PQ signer type is roadmap work
10 Starknet 61 0/3 Experimental Falcon-512 account demonstrated on mainnet STARK proving is hash-based; full consensus stack not credited as PQ-safe Not PQ-safe · public by default Not full-stack · account/hash agility only; full PQ stack not demonstrated Falcon / FIPS 206 pending · experimental / unaudited Not end-to-end PQ; experimental account-level progress
11 Sui 66 0/3 ML-DSA-65 native accounts built; SLH-DSA vault path built; rollout pending Not PQ-safe · no PQ consensus credited Not PQ-safe · no PQ privacy rail credited Crypto-agile account path; mainnet vaults targeted 2026, native ML-DSA accounts Q1 2027 FIPS 204 ML-DSA-65 + FIPS 205 SLH-DSA selected Not end-to-end PQ today; production rollout pending
12 Aptos 56 0/3 Not PQ-safe live · SLH-DSA feature-gated Not PQ-safe · no PQ consensus credited Not PQ-safe · public by default Not full-stack · authorization path only; production stack migration not demonstrated FIPS 205 path · not live mainnet auth Not PQ compliant today · FIPS 205 path exists; live mainnet auth not credited
13 NEAR 63 1/3 ML-DSA account/access-key signing live Consensus still classical; PQ consensus targeted by end-2027 Not PQ-safe · no PQ privacy credited Not full-stack · account/access-key agility only; consensus/privacy remain non-PQ FIPS 204 account only · live at account/access-key level; not chain-wide Partial PQ: FIPS 204 account-level support live
14 Algorand 62 1/3 Native Falcon-1024 accounts live on Mainnet since August 2026 Consensus/VRF still includes classical ECC dependencies Not PQ-safe · no PQ privacy credited Native PQ accounts live; broader consensus/VRF migration underway Falcon live; FN-DSA / FIPS 206 standardization still pending Partial PQ: native account authorization live, full stack incomplete
15 XRP Ledger 55 0/3 secp256k1 / Ed25519 production signatures remain classical Validator-level PQ testing/hybrid work underway Not PQ-safe · confidential crypto not PQ-credited Multi-phase roadmap with active testing; full transition targeted no later than 2028 Testing NIST-recommended candidates; hybrid Devnet transition planned Not PQ compliant today; full PQ readiness targeted by 2028

Source-order note: this table deliberately preserves the order supplied in the benchmark rather than re-ranking by score. “PQ Core” is the source's 3-layer coverage field. The statements above are source-derived benchmark assessments, not independently re-scored in this HTML.

What closes the readiness gap
Base infrastructurePQ-capable transaction authorization, verification, validator/consensus signing and upgrade paths.
Custody & privileged controlsPQ protection for custody, mint/burn, pause, freeze, upgrade and administrative authority.
Identity & token controlsPQ-safe compliance claims, permits, tokenized-vault and policy authorization.
SettlementPQ-capable settlement authorization and infrastructure without a defeating classical fallback.

Remediation path: PQ-native base infrastructure and settlement, PQ Custody SDK, PQ-ONCHAINID, PQ-Permit and PQ-4626 map directly to these control requirements. For Hyperledger Besu specifically, the next section separates existing-network hardening from a greenfield PQ-Safe Ledger path. Remediation is credited in QVaR only when controls are actually deployed.

Concrete remediation path

Hyperledger Besu: From QVaR Exposure to a Deployable Post-Quantum Protection Boundary

The benchmark identifies standard Besu as a classical control surface across transaction authorization, validator signing, P2P/node credentials, privacy dependencies and custody workflows. EternaX provides two deployment paths: harden an existing Besu network without replatforming, or deploy a PQ-safe Besu stack from genesis.

Existing Besu networks

Harden the live network without replacing it

PQ Privacy Overlay Post-quantum payload confidentiality and sender authentication alongside existing Besu. No consensus change, no binary fork, and no validator migration required for the core overlay profile.
PQ tokenization controls PQ Vault, PQ-ONCHAINID, PQ-Permit and PQ-4626 protect issuer authority, compliance claims, permit approvals and tokenized-vault governance.
PQ Custody SDK Adds a post-quantum approval/authorization gate around existing MPC or HSM custody workflows without replacing the custodian.
Coverage boundary: these modules protect specific application, privacy and custody surfaces; unchanged Besu consensus and outer network authorization remain classical unless the ledger layer is also migrated.
Greenfield Besu networks

Deploy PQ-Safe Ledger from genesis

PQ consensus QBFT validator authentication using SLH-DSA.
PQ P2P / node credentials Post-quantum protection for node communication and network identity.
PQ transaction authorization Native SLH-DSA transaction-signing path plus SLH-DSA / ML-DSA verification primitives.
Integrated PQ privacy + crypto-agility PQ Privacy Overlay integrated into the ledger architecture with governed algorithm-rotation paths.
Coverage boundary: PQ-Safe Ledger extends protection into consensus, P2P, native transaction authorization and privacy. Tokenization modules and PQ Custody SDK can be layered on top.
QVaR control surface → EternaX Besu remediation
Private payloadsPQ Privacy Overlay
Private sender authenticationPQ Privacy Overlay
Tokenization authorityPQ Vault / PQ-ONCHAINID / PQ-Permit / PQ-4626
Consensus & validatorsPQ-Safe Ledger
P2P / node identityPQ-Safe Ledger
MPC / HSM custodyPQ Custody SDK
QVaR relevance: the exposed Besu control surfaces map directly to deployable remediation layers. Existing networks can protect selected application, privacy and custody surfaces incrementally; new networks can extend post-quantum protection into consensus, P2P identity, native transaction authorization and privacy from genesis.

Migration Readiness Gap: 26 of 28 Lack a Public End-to-End PQ Path

The core institutional finding is a migration-readiness gap. MRS measures preparedness and future risk trajectory; it does not reduce current Asset or Flow QVaR merely because an organization has announced a plan. NIST and EO timelines remain planning and scope signals as described below.

EternaX 2030 planning benchmark. For comparability, this report uses 2030 as a board-level planning checkpoint: has the programme inventoried cryptographic dependencies, selected migration paths, and begun production transition? Crossing this benchmark is labelled a migration exposure window, not automatically a compliance violation.
MODELED SCENARIO · NAMED PROGRAMMES
Illustrative Migration Windows vs the 2030 Planning Benchmark
A supplementary planning scenario for high-profile programmes in the QVaR register. Bars show illustrative migration windows; the red line is 2030 board-level planning checkpoint. This visual does not predict legal non-compliance.
2026202820302032203420362038
Coinbase Custody
2037
MRS 0.00
Tether / USDT
2037
MRS 0.00
Fireblocks
2037
MRS 0.00
Circle / USDC
2036
MRS 0.00
Anchorage Digital
2036
MRS 0.00
BlackRock / BUIDL
2036
MRS 0.00
BitGo
2036
MRS 0.00
Ondo Finance
2035
MRS 0.00
Broadridge / Canton
2035
Partial / active migration
JPMorgan / JLTXX
2034
MRS 0.00
Solana
2033
Public migration work
Ethereum
2032
Public PQ roadmap
Modeled migration window 2030 planning benchmark Migration exposure window after benchmark

Scenario basis: the bars reproduce the report's earlier institution-level planning model as an illustrative schedule, not a forecast of when any institution will actually complete migration. Public roadmap information is reflected where available; all other bars are scenario assumptions used to visualize planning risk. MRS remains the report's formal readiness measure.

SignalWhat it actually meansApplicability
NIST IR 8547Initial Public Draft transition guidance; proposed deprecation/disallowance timelines vary by algorithm/security strength.Planning guidance, not a universal private-sector statute.
EO 14412Federal HVAs/high-impact systems: PQ key establishment by 2030; PQ digital signatures by 2031.Direct Federal scope; broader critical-infrastructure assistance.
FAR processEO directs a proposed FAR rule for covered contractors to comply with applicable FIPS by end-2030.Contractor obligations depend on the resulting rule and coverage.
FIPS 140-2 transitionFIPS 140-2 validations remain active through Sep. 21, 2026; only FIPS 140-3 validations remain active from Sep. 22.Cryptographic-module validation transition; not itself a PQC deadline.

Primary sources: NIST IR 8547 · Executive Order 14412 · NIST CMVP FAQ.

QVaR Verification Standard: Reproducible Evidence for Quantum Remediation

QVaR should not rely only on narrative claims. The strongest evidence package is a reproducible controlled test: deploy a representative classical control surface, demonstrate what compromised classical authorization permits, deploy the corresponding PQ-protected control, replay the same authorization attempt, and publish the code, configuration and verifiable transaction or protocol evidence.

StepEvidence requiredPublication rule
1. Classical setupOpen contract/configuration and exact cryptographic control surface.Must be reproducible.
2. Classical compromise demonstrationTransaction or protocol action demonstrating authority after key compromise.Clearly labelled as a controlled test, not a real institution breach.
3. PQ-protected setupSame business function with documented PQ authorization layer.Architecture and assumptions disclosed.
4. ReplaySame unauthorized action rejected under PQ control.Publish transaction hash/log or equivalent verifiable artifact.
5. MappingMap only the verified control pattern to real deployments; do not claim identity of internal architecture unless publicly evidenced.Confidence grade required.

This section defines the verification standard. It does not claim that a live proof artifact is attached to this Q3 2026 report; only completed, reproducible artifacts should be labelled verified.

How to Reduce QVaR: Post-Quantum Remediation Paths

Besu is a concrete example of the remediation model. For an existing institutional Besu network, EternaX can add PQ privacy, tokenization and custody controls incrementally. For a greenfield network, PQ-Safe Ledger extends the protection boundary into consensus, P2P and native transaction authorization.

QVaR should connect directly to remediation. The remediation stack starts with the base infrastructure itself: transaction authorization, validator/consensus signing, cryptographic verification, privacy dependencies and upgrade paths must become post-quantum capable. Application-layer controls such as custody, identity, permits and tokenized-vault authorization then sit on top of that foundation.

QVaR componentControl surfacePost-quantum remediationAvailable today
PQ-safe base infrastructureTransaction authorization, validator/consensus signing, cryptographic verification, privacy dependencies and upgrade paths are quantum-vulnerable or non-agile.EternaX PQ-native base infrastructure / settlement layer — signature-agile PQ authorization, PQ-ready verification and settlement primitives designed to remove classical single points of cryptographic failure.
Admin key authorityMint, burn, pause, upgrade, proxy ownerDual-gate PQ authorization: SLH-DSA identity anchor + signature-agnostic threshold, layered beneath existing custodyEternaX PQ Custody SDK
Compliance claimsKYC/AML assertions, investor accreditation, ONCHAINIDPQ-safe claim issuance: SLH-DSA-signed claims verified on-chain via PQ precompileEternaX PQ-ONCHAINID
Permit/approval authorityERC-2612 permit, delegated approvalsPQ-safe permit signatures replacing ECDSA EIP-712EternaX PQ-Permit
Vault governanceERC-4626 admin, deposit/withdraw, yieldPQ-safe vault authorization with SLH-DSA admin verificationEternaX PQ-4626
MPC custody keysECDSA threshold shares across MPC nodesPQ authorization gate before MPC signing gate; existing provider preservedEternaX PQ Custody SDK
Settlement infraValidator keys, consensus, finalityPQ-native chain: SLH-DSA accounts, SILMARILS auth, ~2% TPS overheadEternaX Pluto / PQ Besu
Immutable contractsFrozen standards, non-upgradeable DeFiNo remediation; assets must migrate to PQ-safe infrastructureNo provider

Illustrative Asset QVaR Reduction: From $3.5B to $1.225B

Illustrative example: a $5B programme with CVF 0.70 and DME 0.00 produces $3.5B Asset QVaR. If deployed, verified PQ remediation achieves DME 0.65 while QCE and CVF remain constant, A-QVaR becomes $1.225B — an exact 65% reduction. A roadmap alone would increase MRS, not reduce current A-QVaR.

Before deployed PQ remediation
$3.50B
Asset QVaR
$5B QCE × 0.70 CVF × (1 − 0.00 DME)
−65%
verified deployed mitigation
After deployed PQ remediation
$1.225B
Asset QVaR
$5B QCE × 0.70 CVF × (1 − 0.65 DME)
What drives the reduction: deployed controls that actually reduce the vulnerable surface — PQ-safe base infrastructure, authorization, custody, identity/compliance and settlement controls. A roadmap alone changes MRS, not current QVaR.

Turn Your QVaR Findings Into a Remediation Plan

Start with a pilot scoping call to map the highest-value cryptographic control surfaces and define a deployable remediation path. Institutions already ready to share settlement and control data can proceed to a confidential Settlement QVaR assessment.

Book a Pilot Call
Already in technical evaluation? Request a Confidential Settlement QVaR Assessment.
FAQ · Quantum Value at Risk

Frequently Asked Questions: QVaR, Post-Quantum Security & Institutional Digital Assets

Last reviewed: September 8, 2026. These answers are written to stand alone for readers, search engines and AI retrieval systems. Time-sensitive network, regulatory and institutional claims should be read with the dated primary evidence in the report and Sources section.

These answers are concise and self-contained so boards, technical teams, journalists, search engines and AI systems can extract the report's definitions and conclusions without losing the methodology caveats.

Core QVaR Definitions & Institutional Exposure

What is Quantum Value at Risk (QVaR)?

Quantum Value at Risk (QVaR) is a framework for measuring post-quantum cryptographic financial exposure. It separates Asset QVaR, Flow QVaR and Settlement QVaR so institutions can distinguish standing value, transaction throughput and attack-window settlement exposure.

How is QVaR different from traditional financial Value at Risk (VaR)?

Traditional financial VaR estimates potential market loss over a defined time horizon and confidence level. QVaR is not statistical market VaR: it measures quantum-related cryptographic exposure and control effectiveness so institutions can compare control surfaces and prioritize post-quantum migration.

What is Quantum-Critical Exposure (QCE)?

Quantum-Critical Exposure (QCE) is the standing dollar value governed by a quantum-vulnerable cryptographic control surface before the Current Vulnerability Factor and deployed mitigation are applied. Depending on the programme, QCE can be circulating supply, AUM, custody assets, network asset footprint or another clearly identified value base tied to cryptographic authority.

How is Asset QVaR, Flow QVaR and Settlement QVaR calculated?

Asset QVaR uses A-QVaR = QCE × CVF × (1 − DME). Flow QVaR uses F-QVaRₕ = QCFₕ × CVF × (1 − DME), where QCF is quantum-critical flow over horizon h. Settlement QVaR additionally applies the effective attack/settlement window and institution-specific loss severity. Migration Readiness Score (MRS) is reported separately and does not reduce current QVaR merely because a roadmap exists.

What does the $796.7 billion Asset QVaR headline mean?

$796.7 billion is the modeled gross, non-deduplicated Asset QVaR across the scored standing-exposure categories in the Q3 2026 register: stablecoins, tokenized funds, custody/MPC and public-chain exposure. It is a vulnerability-adjusted exposure measure, not a forecast that $796.7 billion will be lost in a quantum attack.

Is the $796.7 billion Asset QVaR figure unique assets at risk?

No. Gross Asset QVaR is intentionally non-deduplicated because the same underlying asset can depend on multiple independent cryptographic control surfaces. It measures modeled control-surface exposure, not unique assets or expected loss.

Why does the QVaR report reference a $318.5 trillion capital-market base?

SIFMA reports $157.8 trillion of global equity market capitalization and $160.7 trillion of global fixed-income securities outstanding for 2025, or $318.5 trillion combined. QVaR uses this only as addressable capital-market context for institutional tokenization, not as current on-chain or quantum-exposed value.

Primary source: SIFMA 2026 Capital Markets Fact Book findings

Is $318.5 trillion already on-chain or guaranteed to be tokenized?

No. The report explicitly does not claim the entire $318.5 trillion capital-market base is already on-chain or will be tokenized by a particular date. The point is that tokenization can progressively place larger portions of financial-market infrastructure under cryptographic controls.

Are USDT, USDC and other major stablecoins quantum-safe today?

Major stablecoins are not automatically end-to-end post-quantum safe because minting, burning, pausing, freezing, blacklisting, upgrades and treasury controls can depend on classical ECDSA or EdDSA authorization and on the security of the underlying chain. A stablecoin should only be described as end-to-end PQ-safe when every material control surface and dependency has verified post-quantum protection.

Does MPC or threshold custody make ECDSA quantum-safe?

No. MPC and threshold signing can materially improve classical key-management resilience, but they do not change the post-quantum security of the underlying ECDSA signature primitive. A threshold ECDSA system remains dependent on elliptic-curve hardness unless a post-quantum authorization path is added.

Post-Quantum Readiness by Network

Is Ethereum quantum-safe?

Ethereum is not end-to-end post-quantum today. The Ethereum Foundation has a dedicated PQ team and a structured Lean Ethereum roadmap targeting core post-quantum infrastructure around 2029.

Primary source: Ethereum.org

Is Solana quantum-safe?

Solana is not end-to-end post-quantum today. Protocol transactions use Ed25519; PDAs are off-curve and have no private keys. The Solana Foundation identifies the Winternitz Vault as a deployed quantum-resistant primitive and describes a broader migration path, but no protocol-wide PQ signature migration is live.

Primary source: Solana Foundation

Is the Canton Network post-quantum safe today?

Canton is not end-to-end post-quantum safe today. Canton reports $6T+ processed monthly and $350B+ daily tokenized U.S. Treasury repo activity; this report uses the explicitly time-bounded monthly throughput for Flow QVaR. Digital Asset states that ML-DSA signing is available behind an experimental flag and broader PQC migration is underway.

Primary source: Canton Network Forum / Digital Asset

Is Hyperledger Besu post-quantum safe, and how can Besu be remediated?

Stock Hyperledger Besu is not an end-to-end post-quantum transaction, consensus, P2P and privacy stack. Existing Besu networks can add PQ privacy, tokenization and custody controls incrementally, while a greenfield PQ-safe ledger can extend protection into validator signing, P2P/node identity, native transaction authorization and privacy. The report maps these Besu control surfaces to EternaX remediation components.

Primary source: Hyperledger Besu QBFT documentation

Is Zcash quantum-safe?

Zcash is not end-to-end post-quantum today. Ironwood NU6.3 activated on mainnet July 28, 2026 and makes Ironwood-pool funds quantum-recoverable, but quantum recoverability is not the same as PQ-safe transaction authorization.

Primary source: Zcash NU6.3

What is the difference between quantum recoverability and quantum-safe authorization?

Quantum-safe authorization aims to prevent a quantum adversary from forging or taking over current authorization. Quantum recoverability focuses on restoring or reclaiming control after a cryptographic failure event. A system can make progress on recoverability while current transaction signatures remain classically vulnerable.

Regulatory & Migration Timelines

Does NIST IR 8547 create a universal 2030 post-quantum deadline?

No. NIST IR 8547 is an Initial Public Draft, not a universal private-sector law. Its proposed transition guidance distinguishes algorithm families and classical security strengths, so institutions should treat the 2030/2035 dates as important migration-planning signals rather than one blanket legal deadline for every blockchain programme.

Primary source: NIST IR 8547 Initial Public Draft

What does Executive Order 14412 require for post-quantum migration?

Executive Order 14412 requires specified U.S. Federal high-value assets and high-impact systems to use post-quantum cryptography for key establishment by December 31, 2030 and digital signatures by December 31, 2031. It also directs a separate FAR rulemaking process for covered contractors.

Primary source: Executive Order 14412

Is the September 2026 FIPS 140-2 transition a post-quantum deadline?

No. The FIPS 140-2 transition is a cryptographic-module validation transition, not itself a post-quantum migration deadline. FIPS 140-2 validations remain active through September 21, 2026, after which the active CMVP programme moves to FIPS 140-3 validations.

Primary source: NIST CMVP FAQ

Remediation, Verification & Evidence

How can an institution reduce Asset QVaR, Flow QVaR and Settlement QVaR?

An institution reduces current QVaR by deploying controls that actually reduce the vulnerable cryptographic surface: post-quantum transaction authorization, validator or consensus signing, verification, privacy, custody, identity/compliance and settlement controls. A roadmap improves Migration Readiness Score but does not reduce current QVaR until mitigation is deployed.

Can post-quantum protection be added without replacing the custody provider or blockchain?

Sometimes. A PQ authorization or policy gate can be added around existing custody, tokenization or privacy workflows without replacing the underlying provider or chain. That protects the covered control surface but does not automatically remove quantum exposure in unchanged chain-level, validator-level or outer authorization dependencies.

What is the QVaR Verification Standard?

The QVaR Verification Standard requires reproducible evidence rather than narrative claims: demonstrate a representative classical control surface in a controlled test, show what compromised classical authorization permits, deploy the corresponding PQ-protected control, replay the same action, and publish the code, configuration and verifiable transaction or protocol evidence.

How often should the Quantum Value at Risk Register be updated?

The QVaR Register is designed as a quarterly research series. Each edition should refresh AUM, supply, custody, network and flow inputs; cryptographic architecture evidence; deployed mitigation; migration readiness; overlap treatment; confidence grades; and methodology changes.

Can an institution challenge or correct its QVaR assessment?

Yes. A named institution can submit primary evidence that materially changes its architecture, exposure input, control-surface mapping, deployed mitigation or migration-readiness assessment. Accepted changes should be reflected in the next edition with a transparent methodology change log.

What do QVaR evidence grades A, B and C mean?

Grade A means primary evidence such as on-chain code, protocol specifications, regulatory filings, issuer attestations or official technical documentation. Grade B means official provider disclosure or high-quality secondary evidence where implementation is not independently inspectable. Grade C means estimated exposure, inferred architecture or market-share analysis and should carry explicit uncertainty.

Network Benchmark: Additional Protocols

Is Arc post-quantum safe?

Arc is not end-to-end post-quantum today. Circle states Arc already supports SLH-DSA for developers and wallets, while core transaction signatures remain ECDSA. Public mainnet is scheduled for September 16, 2026.

Primary source: Circle

Is Tempo post-quantum safe?

In the supplied benchmark, Tempo scores 54 and receives 0/3 core PQ coverage today. No live PQ signature, PQ consensus or PQ-durable privacy layer is credited, and the authentication interface is not treated as full-stack migration.

Is Stellar post-quantum safe?

In the supplied benchmark, Stellar scores 37 and receives 0/3 core PQ coverage today. Ed25519 accounts remain classical, no PQ consensus layer is credited, and public-by-default operation does not provide PQ confidentiality.

Is Starknet post-quantum safe?

In the supplied benchmark, Starknet scores 61 but receives 0/3 full-layer PQ coverage. A Falcon-512 account demonstration is treated as experimental, and STARK proving is not treated as equivalent to end-to-end PQ-safe consensus, privacy and transaction authorization.

Is Sui post-quantum safe?

Sui is not end-to-end post-quantum today. Sui has built ML-DSA-65 native accounts and an SLH-DSA vault path; quantum-safe vaults are targeted for Mainnet in 2026 and native ML-DSA account authentication for Mainnet in Q1 2027.

Primary source: Sui

Is Aptos post-quantum safe?

In the supplied benchmark, Aptos scores 56 and receives 0/3 live PQ core coverage. The SLH-DSA path is feature-gated rather than live mainnet authorization, and consensus/privacy are not credited as PQ-safe.

Is NEAR post-quantum safe?

NEAR has live ML-DSA account/access-key signing. Consensus remains classical and NEAR targets post-quantum consensus by the end of 2027. The benchmark therefore gives NEAR partial 1/3 coverage.

Primary source: NEAR

Is Algorand post-quantum safe?

Algorand has native Falcon-1024 accounts live on Mainnet since August 2026 and Falcon-based State Proofs, but consensus and VRF dependencies are not yet fully post-quantum. The benchmark therefore gives Algorand partial 1/3 coverage.

Primary source: Algorand

Is XRP Ledger post-quantum safe?

XRPL is not post-quantum today. Ripple is actively testing quantum-resistant cryptography and hybrid migration paths and targets full post-quantum readiness no later than 2028.

Primary source: Ripple

Institutional Adoption & Market Infrastructure

Why is DTCC important to Quantum Value at Risk (QVaR)?

DTC currently custodies more than $114 trillion of assets. DTCC processed live production trades using DTC-tokenized assets with about 40 participating firms in July 2026 and plans to launch the DTC Tokenization Service in October 2026. The significance for QVaR is that tokenization is moving into core market infrastructure, increasing the value dependent on cryptographic control surfaces.

Primary source: DTCC

How much institutional tokenized repo and collateral flow is already live?

Broadridge reported that its Distributed Ledger Repo platform processed $351 billion in average daily repo transactions and $7.4 trillion of total volume in August 2026. DLR is a live institutional tokenized financing and collateral workflow within the Canton ecosystem and is therefore relevant evidence for Flow QVaR, but it is not added again to Canton Flow QVaR.

Primary source: Broadridge

How large is BlackRock's institutional digital-asset footprint?

BlackRock states that it has nearly $150 billion in AUM connected to digital assets, including the world's largest tokenized treasury fund, approximately $65 billion of stablecoin reserves and nearly $80 billion of digital-asset ETPs. The figure is institutional-adoption context, not a standalone QVaR calculation.

Primary source: BlackRock

Advanced QVaR Framework Questions

What are Asset QVaR and Flow QVaR, and how are they different?

Asset QVaR measures standing economic value governed by vulnerable cryptographic controls and is expressed in dollars at a point in time. Flow QVaR measures vulnerability-adjusted quantum-critical transaction throughput over a defined period such as dollars per day, quarter or month. Because their units differ, Asset QVaR and Flow QVaR must not be added together.

Why does the report use Canton for Flow QVaR rather than adding $6T to Asset QVaR?

Canton explicitly publishes a $6T+ processed-monthly metric, so this report uses that time-bounded figure as transaction throughput for Flow QVaR rather than silently treating it as unique assets outstanding. Canton also uses $6T+ tokenized-RWA language elsewhere, which is why the report keeps the flow and stock interpretations separate unless the underlying asset-inventory definition is independently reconciled.

Why does Migration Readiness Score (MRS) not reduce current QVaR?

A migration roadmap does not change the cryptographic primitive protecting transactions today. MRS therefore measures preparedness and future risk trajectory, while only Deployed Mitigation Effectiveness (DME) can reduce current Asset or Flow QVaR in the model.

What is Settlement QVaR, and what data is needed to calculate it?

Settlement QVaR estimates the value that can become economically exposed during a defined compromise-to-detection-to-containment and settlement window. It requires institution-specific data such as transaction limits, compromised key/control scope, finality, DvP or netting, reversibility, monitoring, detection and containment time, recovery mechanisms and loss severity.

Evidence Standard and Confidence Grades

Named-institution scoring is only useful if a third party can reproduce the inputs. Each future row-level evidence page should expose the dated AUM/supply/flow source, cryptographic architecture source, CVF rationale, any deployed mitigation evidence, separate MRS evidence, overlap treatment and calculation. Named institutions may submit primary evidence that materially changes an architecture, exposure input or migration-readiness assessment; accepted changes should be reflected in the next quarterly edition with a transparent methodology change log.

GradeEvidence qualityHow it should be used
APrimary on-chain code, protocol specification, regulatory filing, issuer attestation, or official technical documentation.Can support direct factual statement.
BOfficial provider disclosure or high-quality secondary source, but internal implementation is not independently inspectable.Use with scope caveat.
CEstimated AUM, inferred architecture, or market-share analysis.Use range/tilde and avoid false precision.

How to Cite This Report

Birla, P., Porechna, D., Feng, C. (2026). "Quantum Value at Risk (QVaR) 2026: $796.7B in Institutional Digital-Asset Exposure to Quantum Risk." EternaX Labs, Q3 2026. https://eternax.ai/quantum-value-at-risk-qvar-institutional-digital-assets-2026.html

Primary Sources, Data Inputs and Related EternaX Research

Standards / regulation: NIST IR 8547; EO 14412; NIST CMVP. Capital markets: SIFMA; DTCC/DTC; BCG; Standard Chartered. Market inputs: CoinGecko historical data; Superstate; Franklin Templeton; Coinbase Institutional; DefiLlama; Broadridge. Protocol sources: Ethereum; Solana; Canton; Arc; Zcash; Sui; NEAR; Algorand; XRPL. Institutional activity: DTCC live production trades; DTCC working group / DTC custody; Broadridge DLR; BlackRock 2026 Chairman’s Letter; Franklin Templeton BENJI; Coinbase Institutional. Network exposure: RWA.xyz network metrics; Canton Network flow metrics.

QVaR is a risk-quantification methodology developed by EternaX Labs. It is a vulnerability-adjusted exposure index, not a prediction of loss and not conventional statistical market VaR. Actual exploitation depends on CRQC capability, cryptographic details, public-key exposure, operational controls and response conditions. Scores are intended to be updated quarterly with a public change log. Next edition: Q4 2026 (December).

Related EternaX research: Already Broken Q1 2026 · Cryptographic Migration Debt · Exposure Map 2026 · Signature Security Ranking · MPC Custody Crisis · Non-Upgradeable Chains · Readiness Benchmark 2026 · Besu Quantum Risk

Founding Team

10+ years at the intersection of blockchain infrastructure, institutional finance, and post-quantum cryptography

Paarrthhh Birla
Paarrthhh Birla
Co-Founder
Ex-Polygon (VP Growth Office); Head of Partnerships, Subspace Protocol; Digital assets strategy at EYP, Advised Visa and State Street; MBA, CPA.
Dariia Porechna
Dariia Porechna
Co-Founder
Cryptographer and distributed systems architect; Head of Protocol, Subspace; Research Engineer, Wolfram|Alpha. Co-author, SILMARILS.
Dr. Chen Feng
Dr. Chen Feng
Chief Scientist
Assoc. Prof. at University of British Columbia; PhD (Toronto); 100+ peer-reviewed papers; Quantum communications, blockchain, TEE privacy. Co-author, SILMARILS.